The UAE recorded 2,588 cyber threat activity indicators between April 2025 and August 31, 2026, as cybercriminals, hacktivist groups and state-linked actors increasingly targeted organisations across the country, according to CloudSEK’s Middle East Cyber Threat Landscape 2025–2026.
The report places the UAE among the most targeted countries in the region and documents activity affecting critical infrastructure, maritime and industrial companies, government bodies, financial-services organisations and other businesses. The threats ranged from ransomware and phishing to dark-web exposure and state-linked cyber operations.
One of the most notable incidents came on April 15, 2026, when hacktivist group Handala targeted UAE critical infrastructure. Handala has historically focused primarily on Israeli organisations, making the UAE incident a significant expansion of its targeting beyond its traditional geography.
CloudSEK also documented increased targeting of UAE organisations by MuddyWater, an Iran-linked cyber group. Its campaigns included phishing attacks using regional airline-themed lures and corporate-document decoys. A separate operation targeted UAE maritime and industrial firms using malware designed to give attackers access to compromised systems.
Ransomware becomes a growing regional concern
The UAE threat picture forms part of a wider rise in ransomware activity across the Middle East.
CloudSEK recorded ransomware activity increasing from 17 threat intelligence feeds in April 2025 to 357 in June 2026, representing more than a 20-fold increase over the April baseline. The June 2026 spike was also nearly ten times higher than the previous month.
Turkey was the most ransomware-targeted country in the region, followed by Israel, the UAE, Egypt and Saudi Arabia. The report found that ransomware groups frequently targeted sectors where disruption can have an immediate operational impact, including facility management, industrial operations, property management, infrastructure and manufacturing.
The UAE was also linked to specific ransomware activity during the reporting period. LockBit5 targeted soeuae.ae in August 2026, while NasirSecurity claimed an operation involving targets including Dubai Airport and UAE Customs, alongside organisations in other countries.
UAE organisations draw growing dark-web interest
Beyond direct attacks, CloudSEK found sustained criminal interest in UAE and Gulf organisations on underground cybercrime platforms.
The report observed a heavy concentration of stolen credentials, initial-access listings and leaked corporate information involving organisations in the UAE, Saudi Arabia and Kuwait. Financial services and government were among the leading sectors appearing in dark-web activity, followed by areas including banking, e-commerce, retail, education and telecommunications.
CloudSEK also documented a campaign involving threat actor xpl0itrs, linked to TeamPCP, in which access to government and financial-services environments in the Middle East was advertised for between $2,000 and $40,000 per victim. The report says UAE government and financial-services entities were among those affected by the campaign.
UAE part of a wider Middle East threat surge
The report shows that the UAE’s cyber threat environment is part of a broader regional pattern.
Israel remained the most targeted country overall, while Turkey recorded 3,419 activity indicators and led the region in ransomware-specific targeting. Saudi Arabia recorded 1,880 indicators, with sustained ransomware and dark-web activity, while Egypt recorded 1,389, including significant hacktivism and underground cybercrime activity.
Across the Middle East, CloudSEK found that the threat landscape was being shaped by three major forces operating at the same time: politically motivated hacktivism, financially motivated ransomware and state-linked cyber espionage.
Government and financial services were the most targeted sectors overall, while critical infrastructure and energy attracted significant attention from advanced threat actors.
AI also begins appearing in cyber operations
The report also identified early signs of artificial intelligence being used in offensive cyber activity.
MuddyWater was documented using Google’s Gemini model for PowerShell code obfuscation, while CloudSEK found evidence suggesting AI-assisted malware development by the IRGC-linked Nimbus Manticore group.
Nimbus Manticore expanded operations across sectors including aviation, defence, telecommunications, software development and government during the reporting period.
UAE critical infrastructure among highest-risk groups
CloudSEK assesses the Middle East cyber threat environment immediately following the reporting period as “ELEVATED-HIGH.”
The report identifies UAE and Saudi critical infrastructure organisations among the groups facing the highest risk from ransomware escalation and advanced cyber actors. It also cautions that the decline in visible hacktivist activity after March 2026 should not be interpreted as a reduction in overall cyber risk, as ransomware and state-linked activity continued on a different trajectory.
CloudSEK’s findings suggest that organisations across the UAE and the wider region are no longer dealing with a single dominant cyber threat, but a combination of financially motivated attacks, politically driven campaigns, underground criminal activity and state-linked operations happening at the same time.
